Post-quantum cryptography, on by default, not on a roadmap
Every channel this creates is already quantum-safe: the tunnel handshake, the key exchange, the signatures on policy and the file transfer. Your firewall, your routing and your addressing stay exactly where they are, and nothing leaves the rack.
It’s not a tier, not an add-on, and not a roadmap item.
The problem isn't a computer that doesn't exist yet
The machine that breaks today’s encryption hasn’t been built. Everyone knows that part, and it’s the reason this keeps getting postponed.
Here’s the part that changes the arithmetic.
Captured
Encrypted traffic captured today can be stored.
Kept, not broken
Nobody has to break your encryption this year. They just have to keep the recording.
Opened later
What was stored can be opened later, when that machine exists. Our CPO calls it by its name: harvest now, decrypt later.
If the answer is ten years, the clock started the day it left the building.
The field usually gets shortened to PQC, and you’ll meet it that way in standards documents and security questionnaires long before anyone says the words out loud in a meeting.
Which channels, which algorithms, and who signed them
Four things, and we list them separately because “post-quantum” on a vendor page usually means only one of them.
The tunnel handshake
When a device connects to a gateway, the key agreement runs the hybrid group p384_mlkem768: ECDH on NIST P-384 and ML-KEM-768, together. An attacker has to break both. The session itself is TLS 1.3 with AES-256-GCM and SHA-256 integrity.
The key exchange
On the same basis as the handshake, with key derivation following NIST SP 800-56C.
The signatures on policy
Company Policy is signed with ML-DSA before it leaves the console. That’s what stops a user turning off what the organisation turned on.
The file transfer
Encrypted exchange between devices runs over the same protected channel. There’s also quantum key distribution built on BB84 for the transfers that need it.
- Hybrid key agreement: ECDH P-384 and ML-KEM-768, together
- TLS 1.3, AES-256-GCM and SHA-256 integrity on every session
- Policy signed with ML-DSA before it reaches any device
- Quantum-safe shown as a property of the link itself
- Documented cryptographic inventory, subsystem by subsystem
- Vault and notes stay local, so data residency holds
The console where the policy gets written is QS-WAN. The agent that carries it onto the device, and that raises the tunnel, is the QNova Client.
Hybrid by design, which is the boring part that matters
Every one of those channels runs the post-quantum algorithm alongside a classical one, not instead of it.
ECDH on NIST P-384
The classical key agreement, kept in place.
ML-KEM-768
Key encapsulation standardised in FIPS 203.
p384_mlkem768
An attacker has to break both, so breaking one buys nothing.
The standards are young
The quantum resistant encryption standards are young, and a flaw found in one of them later shouldn’t take your network with it.
You're adding a floor
Running both means the security is never worse than the classical baseline it replaces. You’re adding a floor, not swapping one.
The migration isn't a cutover
It also means the migration isn’t a cutover. That’s the difference between a project and a change.
The document a regulator asks for first
The system provides a documented cryptographic inventory per subsystem: what algorithm runs where, in which component, for which purpose.
This is the artefact that turns up first in an audit, a security questionnaire or a tender, and it’s unpleasant to assemble after the fact from a network nobody designed for it. Here it’s a property of the system rather than a spreadsheet somebody keeps up to date on a good week.
Alongside it sits crypto agility, which is the ability to change algorithm without rebuilding the network. If a standard moves, and standards move, that’s the difference between a configuration change and a migration.
Key encapsulation, in the tunnel handshake and the key exchange.
Signatures on Company Policy before it reaches the fleet.
The set of algorithms lines up with CNSA 2.0.
Key derivation.
The risk management side.
What algorithm runs where, in which component, for which purpose.
The same fact reads differently at the two ends of the building
The person who runs the network wants to know what breaks on Monday. The person who signs the contract wants to know what it costs to answer question 47 of a tender, and those are not the same worry.
Nothing moves
Your firewall stays, your routes stay, your addressing stays. The tunnel terminates on a gateway you place, in the network you already drew.
Failures that name themselves
When a handshake fails, the client says which failure it was: authentication rejected, revoked certificate, weak CA, unknown authority, recursive routing, unreachable server, port collision. Each one gets its own message and its own automatic remedy, instead of one red banner that lands on your help desk with the rest left to you.
Transport you choose
Pick the gateway and the configuration is rewritten in place. Driver profiles for Wintun, TAP-Windows and OpenVPN DCO, and UDP or TCP per gateway profile.
The audit answer, already written
A documented cryptographic inventory per subsystem is the artefact that turns up first in a tender or a security questionnaire. Here it’s a property of the system rather than a spreadsheet somebody updates on a good week.
No migration project
Hybrid means the post-quantum algorithm runs next to the classical one, not instead of it, so security is never worse than the baseline you already had. There’s no cutover to schedule and nothing to roll back at 3am.
It isn't a tier
Post-quantum cryptography is on in the cheapest configuration we sell. No add-on line on the quote, and no upgrade conversation waiting for you in eighteen months.
Which cryptography runs, between which components, and when
Three flows, drawn for the network or security engineer who has to sign off on them. Asymmetric cryptography establishes keys and signs policy. Symmetric cryptography protects the data once those keys exist.
- Key establishment, asymmetric, or QKD on the optional path
- Data encryption, symmetric
- Identity credential, certificate and private key, never encryption
- Operation, derivation, hash or XOR
- Component, device, gateway, console, KMS
- Protected channel, with encrypted data moving
- Identity provisioning, issued by the Control Tower CA
Keys are established first, then the traffic is encrypted
QNova Client and Gateway. Hybrid group p384_mlkem768: ECDH on NIST P-384 and ML-KEM-768 both go into the session secret.
Before establishing the encrypted tunnel, the Gateway verifies the cryptographic identity of the QNova Client
The Control Tower, as the certificate authority, provisions an identity to the QNova Client and to the Gateway. On connection the client presents its device certificate and the Gateway verifies it.
Files cross a protected channel, with QKD where a transfer requires it
Direct transfer between devices by default. The QKD path is optional and drawn apart.
Three steps, and the first one is somebody pressing one button
Here’s what actually has to happen for any of this to be true, from a laptop in a hotel to the screen where you decide things. Nobody in this story reads a cryptography paper.
One button, in a hotel, at 7am
Someone who’ll never log into your console opens the QNova Client and connects. The key agreement runs the hybrid group, and the client shows quantum-safe as a property of that link rather than a line buried three panes deep in settings. The tunnel can also come up at sign-in on its own, and optionally without showing the window at all. It knows about suspend and resume, it survives a reboot, and Force disconnect sits there for the moment something has to come down now.
You find out, and you didn't have to ask anyone
The same connection lands in QS-WAN against the gateway profile you wrote: which gateway, which transport, which user. You’re not taking the device’s word for it either, because Company Policy is signed with ML-DSA before it leaves the console, so nobody downstream gets to apply a version you didn’t sign. One honest caveat, because you’d find it anyway: the record in QS-WAN is authoritative about what you decided, and a device that’s offline hasn’t picked it up yet. It converges when it comes back.
The document a regulator asks for first
Now you can answer the question that used to eat a week. The documented cryptographic inventory says what algorithm runs where, in which component, for which purpose, subsystem by subsystem. And when a standard moves, and standards move, crypto agility means you change the algorithm instead of rebuilding the network. That’s the difference between a configuration change and a project with its own steering committee.
Your firewall, your routing and your addressing stay exactly where they are
| Layer | What you already have | What comes in | Does it move? |
|---|---|---|---|
| Firewall and routing | Your firewall, your routes, your addressing | Nothing. The tunnel terminates on a gateway you place | No |
| Remote access | A VPN client and a concentrator | The QNova Client and hybrid key agreement p384_mlkem768 | No |
| Session security | Whatever your current tunnel negotiates | TLS 1.3, AES-256-GCM, SHA-256 integrity, SP 800-56C derivation | No |
| Identity | Your directory and your certificates | Certificate-based device authentication, ML-DSA signatures on policy | No |
| Endpoints | Windows and Linux machines | One signed agent, one connect button | No |
| Audit evidence | A spreadsheet somebody keeps current | A documented cryptographic inventory per subsystem | No |
Replace the tunnel, or keep it and add the layer
Replace the tunnel you were going to re-procure anyway
If the VPN is already on this year’s list, this takes its place and brings the post-quantum part with it at no extra line.
- One signed agent instead of a separate VPN client
- Gateway choice, transport and driver profile, set per gateway
- Failures come back named and remedied, not as "tunnel is down"
- One authentication certificate per enrolled device
Keep what you run and put the layer next to it
If your VPN isn’t going anywhere this year, the gateway sits inside your own addressing and carries the traffic that has to stay private for a decade.
- Hybrid by design, so the floor is never lower than your classical baseline
- Runs on a gateway you place, in the network you already have
- The cryptographic inventory covers what's there, which is how you find the rest
- QKD file transfer plugs into a key management entity you already run
Integrations and dependencies
Microsoft Entra ID
An embedded sign-in window fetches the profile, and the token is what authorises the certificate the tunnel then authenticates with.
Active Directory (LDAP and ADFS)
The client checks the signed-in Windows account against the domain and asks for a certificate bound to that security identifier.
QKD key management entity
For file transfer, a standard KMS interface over mutually authenticated TLS, so it fits a QKD network you already have instead of demanding a parallel one.
Platform coverage, stated straight
The tunnel is in production on Windows and Linux, with macOS and iOS planned, because we publish support one column at a time instead of a tick across the whole row.
Where we come into this
QuantumNova was founded in 2023 out of quantum computing research, and we were among the first in Europe to put post-quantum cryptography into a product organisations actually run rather than into a paper.
We’d rather be precise than impressive about that. An accreditation isn’t an endorsement. It means we met a standard and somebody checked.
- Accredited by Portugal's National Cybersecurity Centre (CNCS)
- Participant in the Digital Europe Programme, for post-quantum projects
- One of Portugal's 10 most promising startups of 2025, EU-Startups, 17 February 2025
- Microsoft has authorised us to distribute kernel drivers
- FIPS 203, FIPS 204, CNSA 2.0 alignment, NIST SP 800-56C and NIST SP 800-37 Rev 2
What this does not do
It doesn’t protect data that leaves your network by another route. It’s the channel that’s post-quantum, not everything you own.
It doesn’t make the rest of your estate quantum-safe by being installed. What it does is stop adding to the pile of recordings that will be readable later, and give you the inventory to see where the rest of the problem sits.
And it doesn’t need a decision from you about quantum computing timelines. It’s on, on the cheapest configuration we sell, whether or not you believe the machine arrives this decade.
Is post-quantum cryptography worth doing if quantum computers don't exist yet?
Yes, if your data has to stay private for longer than a few years. Encrypted traffic captured today can be stored and opened later, once a machine that can break it exists. That’s called harvest now, decrypt later, and it doesn’t need the machine to arrive this year. It only needs the recording to survive.
What does hybrid mean, and why not just use the post-quantum algorithm?
Hybrid means the post-quantum algorithm runs alongside a classical one, not instead of it. In the handshake that’s ECDH on NIST P-384 together with ML-KEM-768, and an attacker has to break both. The post-quantum standards are young, and a flaw found in one of them later shouldn’t take your network down with it. You’re adding a floor, not swapping one.
Which standards does this map to?
FIPS 203 for key encapsulation and FIPS 204 for signatures, aligned to CNSA 2.0. Key derivation follows NIST SP 800-56C, and the risk management side lines up with NIST SP 800-37 Rev 2. There’s also a documented cryptographic inventory per subsystem, which is the thing most questionnaires ask for before they ask for anything else.
Do we pay extra for the post-quantum part?
No. It’s on by default, in the cheapest configuration we sell. It isn’t a tier, an add-on or a roadmap item, and it doesn’t need you to hold an opinion about quantum computing timelines.
What happens when a standard changes, or the certificate authority has to be rotated?
Changing algorithm is a configuration change, not a rebuild, and that’s what crypto agility buys you. Rotating the certificate authority is a different job: it needs every gateway connected and it restarts a service, so it’s a scheduled operation rather than a button you press on a Tuesday afternoon. We’d rather say that now than in a change window.
Bring the questionnaire
Tell us which tunnel you run today and which question on the tender you still can’t answer. We’ll show you the same connection coming up on your own network, and hand you the cryptographic inventory that goes with it.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.